CVE-2026-26718
CRITICALxxl-job-admin 3.0.0 - Cross-Site Request Forgery via Glue IDE Shell Script Modification Endpoint
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2026-26718. PoCs published by Ibrahim-Sartawi.
AI-analyzed exploit summary This repository demonstrates a CSRF vulnerability in xxl-job-admin < 3.4.0, allowing unauthorized modifications to Glue IDE shell scripts via a crafted HTML form that bypasses CSRF token validation. The PoC includes a functional exploit that executes arbitrary shell commands when submitted by an authenticated administrator.
Description
A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. The affected endpoint lacks proper CSRF token validation and accepts arbitrary HTTP methods via a permissive request mapping
Exploits (1)
This repository demonstrates a CSRF vulnerability in xxl-job-admin < 3.4.0, allowing unauthorized modifications to Glue IDE shell scripts via a crafted HTML form that bypasses CSRF token validation. The PoC includes a functional exploit that executes arbitrary shell commands when submitted by an authenticated administrator.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N